Cross-Site Scripting Vulnerabilities in Ubercart Module for Drupal
CVE-2008-1428
Currently unrated
Summary
The Ubercart module for Drupal has multiple vulnerabilities that allow attackers to execute arbitrary scripts by injecting malicious content into product attribute values. This could lead to unauthorized access, data theft, or manipulation of user sessions, putting affected sites at significant risk. It's crucial for users of the Ubercart module to update to the latest version to mitigate these security flaws.
References
Timeline
Vulnerability published
Vulnerability Reserved